Decent firewall/ssh blocking?

Ask questions about Arch Linux ARM. Please search before making a new topic.

Decent firewall/ssh blocking?

Postby Mazdaspeed6 » Thu May 03, 2012 11:56 pm

While poking around in my logs folder i came across a large auth.log file. I opened it and found ALOT of entries of random username attempts to access ssh on my POGO V2. I dont see where they gained access but this has me worrying. How can stop this? I tried fail2ban and kept getting errors when starting it and the same with SSHGUARD that i beleive was related to the errors with iptables i was getting. I only really need to access SSH locally, so would it be best to some how block SSH to allow only local IP's or is there a better way?
I know that strong passwords are the best way to prevent this but wanted to know what else i can do

thanks
Mazdaspeed6
 
Posts: 54
Joined: Sun Jul 17, 2011 1:13 am

Re: Decent firewall/ssh blocking?

Postby WarheadsSE » Fri May 04, 2012 12:04 am

Either turn off port forwarding, since the device shouldn't be directly attached to the internet, or change the port for obscurity. Either way consider switching to key based authentication instead of password over SSH.
Core Developer
Remember: Arch Linux ARM is entirely community donation supported!
WarheadsSE
Developer
 
Posts: 6807
Joined: Mon Oct 18, 2010 2:12 pm

Re: Decent firewall/ssh blocking?

Postby Mazdaspeed6 » Fri May 04, 2012 12:11 am

i will probably just disable port forwarding then. I am also running FTP. is there a way to further secure that?

I have transmission/deluge running as a daemon as well but i dont think they are any risk..there password protected as well.
Mazdaspeed6
 
Posts: 54
Joined: Sun Jul 17, 2011 1:13 am

Re: Decent firewall/ssh blocking?

Postby WarheadsSE » Fri May 04, 2012 12:28 am

Personally I use sftp instead of FTP.

Edit: dyac
Core Developer
Remember: Arch Linux ARM is entirely community donation supported!
WarheadsSE
Developer
 
Posts: 6807
Joined: Mon Oct 18, 2010 2:12 pm

Re: Decent firewall/ssh blocking?

Postby TheWalt » Fri May 04, 2012 1:42 am

For SSH access I changed the incoming port to something obscure in the router and mapped it to port 22 on the actual device, pretty easy to do. Also, I use a program like filezilla that supports secure ftp over ssh to transfer files to eliminate the need for FTP running.
TheWalt
 
Posts: 23
Joined: Fri Feb 17, 2012 12:22 am


Return to User Questions

Who is online

Users browsing this forum: No registered users and 16 guests